Ensuring Compliance with Azure Policies
Pluralsight Hands-On Lab — Identity & Governance
At a Glance
| Platform | Pluralsight |
| Category | Azure Governance |
| Lab Type | Guided + Challenge Mode |
| Environment | Azure Portal |
| Completed | 2026 |
Overview
Azure Policy is a governance tool that enforces organizational standards and assesses compliance across Azure resources. In this lab, I acted as an Azure security engineer tasked with ensuring resource compliance through policy assignments. I assigned two policies at the resource group scope: one to require a Cost Allocation tag on all resource groups, and one to automatically inherit that tag from the parent resource group when missing. I then deployed a virtual network, observed automatic tag inheritance, and ran a remediation task to bring existing non-compliant resources into compliance.
What I Did
- Assigned the built-in policy "Require a tag on resource groups" scoped to the lab resource group, with tag name "Cost Allocation" and a custom non-compliance message
- Assigned the built-in policy "Inherit a tag from the resource group if missing" with a user-assigned managed identity (mi-policytags) for remediation authorization
- Applied a Cost Allocation tag with value "IT" directly to the resource group
- Created a new virtual network (PolicyVnet2) without a tag and observed it automatically inherit the Cost Allocation tag from the parent resource group due to the policy
- Confirmed that PolicyVnet1, created before the policy was assigned, did not have the tag — demonstrating that policies apply going forward but do not retroactively remediate
- Created a remediation task for the "Inherit a tag from the resource group if missing" policy, scoped to the existing location, with resource compliance re-evaluation enabled
- Waited for the remediation task to complete and confirmed PolicyVnet1 had inherited the Cost Allocation tag
← Back to Pluralsight Labs